RSS   Podatności dla 'Eurologon cms'   RSS

2007-11-29
 
CVE-2007-6185

CWE-22
 

 
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a download action, as demonstrated by a certain PHP file containing database credentials.

 
2007-11-28
 
CVE-2007-6164

CWE-89
 

 
Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) reviews.php, (2) links.php and (3) articles.php.

 


Copyright 2024, cxsecurity.com

 

Back to Top